<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: QOS for multiple user addresses in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/220041#M63494</link>
    <description>&lt;P&gt;if iam going to restrict upload and download&lt;BR /&gt;&lt;BR /&gt;i will create 2 qos profiles and assign to 2 classes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then add 2 physical interfaces , one for each direction (download and upload) and&amp;nbsp; add the qos profile here&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;now, in the qos policy section , i will create 1 policy or two?&amp;nbsp; &amp;nbsp;&lt;BR /&gt;if 2 polcies , one fron trust to untrust and the other from untrust to trust // which one to add the class of upload and which one to add the class of download&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;</description>
    <pubDate>Sun, 01 Jul 2018 12:20:42 GMT</pubDate>
    <dc:creator>AKabary</dc:creator>
    <dc:date>2018-07-01T12:20:42Z</dc:date>
    <item>
      <title>QOS for multiple user addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/219662#M63412</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i need to create a qos policy to limit downloads and uploads of user addresses objects created on palo alto device&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i know that i will ceate a qos profile for down and up&amp;nbsp; , choose a class , priority and type guaranteed and max BW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then create a qos policy and qos interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1-regarding the qos policy , do i need a policy for upload and policy for download??&lt;BR /&gt;&lt;BR /&gt;2-regarding the qos egress interface&amp;nbsp; and source subnet , will it difer between the upload and the download&lt;BR /&gt;&lt;BR /&gt;3-if i make a download policy and apply it on say 10 user addresses , will that BW be given to the whole group f users or for&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; each user individually&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;\thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 12:16:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/219662#M63412</guid>
      <dc:creator>AKabary</dc:creator>
      <dc:date>2018-06-28T12:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: QOS for multiple user addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/219852#M63438</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83945"&gt;@AKabary&lt;/a&gt;&amp;nbsp;y&lt;/SPAN&gt;ou are right, you will need a QoS profile and assign it to the Egress interface. Broadly speaking, you can have up to 8 Classes for traffic type. So lets say that you will create Class8 restricting downloads to particular value. The QoS policy can match traffic on specified criteria, but as an action you can only choose 1 of the classes or assign DSCP/ToS to be processed by another device.&lt;/P&gt;&lt;P&gt;So the answers will be:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;I think you need to clarify what do you mean by upload and download. You need to really follow the Palo Alto policy logic. For example if user initiates a session to dropbox your QoS policy will be matching on source user, application Dropbox and action assign to class, then the policy will match this session regardless if the user is uploading or downloading files. Bandwidth restrictions will, however be applied only on the egress interface. So if you have restrictions on the external interface, but not on the internal, the policy will be the same, but only upload will have its bandwidth restricted.&lt;/LI&gt;&lt;LI&gt;The egress interface will differ for download and upload. Regarding source subnet, if you mean in policy, the logic is based on you policy and the type of traffic you need to match. If you are referring to “Source Subnet” configured under “QoS Interface”, then it will differ.&lt;/LI&gt;&lt;LI&gt;The policy is not relevant, but the action, which for example can be “Class 8”. You can have different conditions assigning traffic to Class 8 and anything assigned to Class 8 will share the Class 8 configured limit per egress interface.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;QoS on Palo Alto is not as granular as some routers from other vendors and it has its limitations. So depending on how advanced you QoS set up need to be, you may need to consider offloading the functionality to another device.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 06:19:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/219852#M63438</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2018-07-02T06:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: QOS for multiple user addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/219854#M63439</link>
      <description>Thank u&lt;BR /&gt;So , the policy can be applied to only obe phy interface&lt;BR /&gt;So by your example if i want to restrict download and upload speed&lt;BR /&gt;&lt;BR /&gt;I need to create 2 qos profiles with 2 classes&lt;BR /&gt;and create 2 policies ,so what will he egress interface be for upload and downoad&lt;BR /&gt;&lt;BR /&gt;Also in the policy for downoad ,the source and destination zones are blurry to me</description>
      <pubDate>Fri, 29 Jun 2018 07:36:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/219854#M63439</guid>
      <dc:creator>AKabary</dc:creator>
      <dc:date>2018-06-29T07:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: QOS for multiple user addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/219855#M63440</link>
      <description>&lt;P&gt;You are mixing the two concepts. Polcies match on sessions, download and upload only realte to in and out interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Presuming that the discussion is around your internal users. Your Upload QoS profile will apply to your external interface. Download will be internal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to apply the restrictions to user web traffic, in your case the policies will probably be always from trusted to untrusted zone assigning the traffic to a class.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 07:52:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/219855#M63440</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2018-06-29T07:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: QOS for multiple user addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/219860#M63445</link>
      <description>Yes the interface is assigned a profile which is assigned a class&lt;BR /&gt;&lt;BR /&gt;Now i will have 2 interfaces ext for upload traffic with its class and profile&lt;BR /&gt;&lt;BR /&gt;Int for download traffic with its class and profile&lt;BR /&gt;&lt;BR /&gt;Now i will create two policies or one policy ?&lt;BR /&gt;In the policy options u select the class&lt;BR /&gt;So i think i create 2 policies?&lt;BR /&gt;</description>
      <pubDate>Fri, 29 Jun 2018 08:04:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/219860#M63445</guid>
      <dc:creator>AKabary</dc:creator>
      <dc:date>2018-06-29T08:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: QOS for multiple user addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/220041#M63494</link>
      <description>&lt;P&gt;if iam going to restrict upload and download&lt;BR /&gt;&lt;BR /&gt;i will create 2 qos profiles and assign to 2 classes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then add 2 physical interfaces , one for each direction (download and upload) and&amp;nbsp; add the qos profile here&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;now, in the qos policy section , i will create 1 policy or two?&amp;nbsp; &amp;nbsp;&lt;BR /&gt;if 2 polcies , one fron trust to untrust and the other from untrust to trust // which one to add the class of upload and which one to add the class of download&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jul 2018 12:20:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/220041#M63494</guid>
      <dc:creator>AKabary</dc:creator>
      <dc:date>2018-07-01T12:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: QOS for multiple user addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/220048#M63495</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83945"&gt;@AKabary&lt;/a&gt;&lt;/P&gt;&lt;P&gt;You only need one QoS policy. This one policy will assign client-to-server and server-to-client traffic to the specified class. And based on this class you can then specify the bandwith/priority for upload and download seperately as already mentionned and explained by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/74884"&gt;@BatD&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jul 2018 17:50:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/220048#M63495</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-07-01T17:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: QOS for multiple user addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/220052#M63498</link>
      <description>But i created 2 classes for 2 qos profiles&lt;BR /&gt;One for upload and one for download&lt;BR /&gt;&lt;BR /&gt;So if it is one qos policy , then which class should i add</description>
      <pubDate>Sun, 01 Jul 2018 20:09:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/220052#M63498</guid>
      <dc:creator>AKabary</dc:creator>
      <dc:date>2018-07-01T20:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: QOS for multiple user addresses</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/220794#M63651</link>
      <description>&lt;P&gt;You only need one QoS Profile.&amp;nbsp; In that profile, you specify your various classes with limits to bandwidth based on the class (lower numbered classes have higher priority).&amp;nbsp; Or, you just define the classes with priority levels and just limit the total bandwidth to the Profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then you create as many QoS Policies as you need to separate your traffic into the classes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Policies separate the traffic into the various classes.&amp;nbsp; The Profile determines what those classes mean and how the traffic is handled.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 23:07:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/qos-for-multiple-user-addresses/m-p/220794#M63651</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-07-05T23:07:57Z</dc:date>
    </item>
  </channel>
</rss>

